Delivery Tier Users

Bloomreach Experience Manager's delivery tier includes four default users:

  • configuser
  • liveuser
  • previewuser
  • sitewriter

configuser

The configuser account requires read access to nearly all nodes in the repository. This user does not require write permissions.

liveuser

The liveuser account is used to render live content. This user should not have write access to any node type.

previewuser

The previewuser account is used to render preview content. The Experience manager preview uses this user, sometimes in combination with the CMS editor or author account. For details, see Experience Manager Preview With Security Delegation. This user should not have write access to any node type.

sitewriter

The sitewriter account is used to persist changes to the repository, such as storing form data or performing workflow actions on documents. By default, sitewriter has write access only to form data. To use the HST workflow manager (WorkflowPersistenceManager), you must grant sitewriter additional permissions. See Configure Permissions when using Workflow in the Delivery Tier for configuration details.

Optional Separate Binaries User

The binaries session pool manages JCR sessions for the binaries servlet when a request does not already have an HstRequestContext. If an HstRequestContext exists, the session returned by HstRequestContext#getSession is used. Typically, this is the liveuser for live content and the previewuser for preview content (such as in Experience manager preview). By default, the binaries user is the same as the liveuser. To use a different user, set the binaries.repository.user.name property in your hst-config.properties file.

Passwords

Starting with Bloomreach Experience Manager 10.0, you can leave the password for all default site users empty in hst-config.properties, or omit the configuration entirely. The users in the repository are configured with:

hipposys:passkey: jvm://

When the HST site web application and the repository run in the same JVM (the standard setup), the HST can obtain a JCR session using only the user name, without a password. The following JVM-enabled users are configured by default:

  1. configuser
  2. liveuser
  3. previewuser
  4. sitewriter

To use a JVM-enabled user without a password:

  1. Ensure the user in the repository has hipposys:passkey = jvm://:

    /hippo:configuration: /hippo:users: /configuser: hipposys:passkey: jvm:// /liveuser: hipposys:passkey: jvm:// /previewuser: hipposys:passkey: jvm:// /sitewriter: hipposys:passkey: jvm://
  2. In hst-config.properties, remove the password for each user or leave it empty. For best results, remove all user-related properties such as default.repository.user.name and default.repository.password.

    Hint: Remove all user-related properties from hst-config.properties when using JVM-enabled users.

Optional

If you use JVM-enabled site users, you can remove the hipposys:password property from each user. This is recommended for production environments. Retain the password only if you need to log in with a site user through the repository servlet at /repository.

Advantages of JVM-Enabled Site Users

JVM-enabled site users eliminate the need to store passwords for site users in external files such as hst-config.properties. If a site user's password changes in the repository, you do not need to update passwords on every cluster node. Additionally, you do not need to manage different passwords for site users across environments.

Share Feedback
Page: /deploy/security-logging/hst-users
Section: Deploy
Category *
Delivery Tier Users | Bloomreach Content Documentation